Help

Your first verified bank change takes about five minutes and needs no third-party account. Email [email protected] for anything else.

Quick start

1. Add a vendor.

After signup you land on Start. Add a vendor, import a CSV (name, contact, phone on file, email domains, bank name, last 4, account type), or click Use sample data for eight labeled fictional vendors. The phone on file is a number you verified yourself, from a contract or an earlier call; it is the only number the app will ever tell you to dial.

2. Open a change request.

Click New change request, pick the vendor, and paste the "updated banking details" email, or upload the .eml, a screenshot, or a PDF; each file is hashed. Click Try a suspicious example to see the flow first. The app extracts the sender address, compares its domain to the vendor's domains on file, and shows a verdict: match, lookalike, or unknown; urgency words are listed. Enter the requested bank name and last four digits only; a full account number is rejected.

3. Make the callback.

The screen shows the phone on file in large type and, if the email contained a number, that one too with a warning never to use it. Call, then record when, who you spoke with, and the outcome. Confirmed moves the request forward; denied marks it as suspected fraud with a one-click internal summary; unreachable or left message keeps it pending.

4. Get the second approval.

A different user in your account approves from the queue or the email notice. A one-person shop can declare a single-approver exception with a reason, printed in bold on the PDF.

5. Wait out the hold, then release.

The hold defaults to 48 hours; change it in Policy, or shorten it at approval for an emergency with a written justification. A request cannot be released before the hold ends. When the reminder arrives, update your payment system, then record the system name and reference; the vendor record picks up the new last four digits and a fresh verified-at date.

6. Download the evidence.

Every request has an evidence PDF: timeline with actors, timestamps and IPs, attachment hashes, domain verdict, callback record, approvals, hold, release, the policy version in force, and an integrity page with the document's SHA-256 and verify link. Reports has the monthly digest and, on Team and Firm, an auditor export for any date range.

Keep the policy current

Policy generates a one-page Vendor Banking Change Policy from your settings, with version history, for the handbook and insurer questionnaires. Each change request records the policy version that was in force when it was opened.

How the domain check works

The sender address is taken from the From line of the pasted message (then Reply-To, then the first address found). Its domain is compared with the domains on the vendor record. Exact matches and subdomains of a domain on file are a match. A domain with the same name and a different ending, one that looks the same once similar characters are swapped (1 for l, 0 for o, rn for m), one within a character or two of the real domain, or one that wraps the vendor's name in extra words is a lookalike. Anything else is unknown. A match proves nothing on its own; the callback is the control.

Account numbers

The app never stores a full bank account number. Last-four fields accept exactly four digits and reject anything longer. Free text (the pasted email, notes, comments, references) is scanned for runs of eight or more digits; each run is replaced with [redacted ····1234] before it is saved, and the page tells you how many runs were redacted.

Accounts and team

Signing up creates an account and makes you its owner. Owners and admins invite teammates from Team; an invitation link expires after seven days and works once. Roles: owner manages billing and roles, admin manages the team and the policy, member works with vendors and change requests. Any user other than the requester can approve a request.

Verify your email address to unlock invitations and any email the app sends on your behalf. Everything else works before verification.

Verifying a hash

Go to Verify and paste a hash: an event hash from a PDF timeline, the SHA-256 of a PDF file, or the body hash printed on its integrity page. The page reports whether it exists, its position in the chain and when it was recorded. No account is needed and nothing about the content is revealed. To compute a file's SHA-256: sha256sum file.pdf on Linux, shasum -a 256 file.pdf on macOS, Get-FileHash file.pdf in PowerShell.

Email

Approval notices go to the other users in your account; hold-ended reminders go to the requester and the approver; the monthly digest goes to owners and admins. Every link the app emails also appears in the app. Outgoing email is limited per account and per hour.

What BankChangeProof does not do

It does not call anyone, validate account ownership, move money, or connect to your accounting system. It records the control you ran and produces the proof. Questions: [email protected].